← Vulnerability feed

Vulnerability record · CVE-2018-12465 · published 29 June 2018

CVE-2018-12465: Micro Focus Secure Messaging Gateway web admin OS command injection

Microfocus · Secure Messaging Gateway

The web administration component of Micro Focus Secure Messaging Gateway (SMG) before version 471 fails to neutralize OS command input, allowing command injection (CWE-77/CWE-78). A privileged authenticated user can run arbitrary OS commands on the SMG server, and the flaw can be chained with CVE-2018-12464 to reach unauthenticated remote code execution.

7.2 CVSS 3.0 High EPSS 80% · top 0.4% CWE-77 · Command injectionCWE-78 · OS command injection
7.2CVSS 3.0 base score, v2 9.0
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that used GWAVA product name (i.e. GWAVA 6.5).

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 7.2 with high confidentiality, integrity and availability impact, very high EPSS, public exploit code, and a chain to unauthenticated RCE, though exploitation requires privileged access unless chained.

What it is

The web administration component of Micro Focus Secure Messaging Gateway (SMG) before version 471 fails to neutralize OS command input, allowing command injection (CWE-77/CWE-78). A privileged authenticated user can run arbitrary OS commands on the SMG server, and the flaw can be chained with CVE-2018-12464 to reach unauthenticated remote code execution.

Impact

An attacker with privileged web admin access gains arbitrary OS command execution on the SMG server, leading to full compromise of the appliance and any data or credentials it handles. Chained with CVE-2018-12464, the same code execution is reachable without authentication.

Attack surface

Reached over the network through the SMG web administration interface (CVSS AV:N). The vector requires high privileges (PR:H) and no user interaction (UI:N), so a valid privileged admin account is needed unless chained with CVE-2018-12464.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.80021, 99.6th percentile) and public exploit code exists on Exploit-DB (45083) plus a detailed write-up, indicating active interest and easy weaponization.

What to do

  • Upgrade Secure Messaging Gateway to version 471 or later; versions prior to 471 are affected.
  • If immediate patching is not possible, restrict network access to the SMG web administration interface to trusted management networks.
  • Enforce least privilege and strong authentication for SMG admin accounts, and audit for unnecessary privileged users.
  • Monitor and apply the fix for CVE-2018-12464 as well, since the two flaws chain into unauthenticated RCE.

Detection

  • Monitor SMG web admin logs for unusual requests or parameters that could carry shell metacharacters.
  • Alert on unexpected child processes spawned by the SMG web server or application service.
  • Watch for outbound connections or command-and-control traffic originating from the SMG server.
  • Review authentication logs for anomalous privileged admin logins or new admin account creation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-12465 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12464Micro Focus Secure Messaging Gateway SQL Injection in Web Admin and QuarantineThe web administration and quarantine components of Micro Focus Secure Messaging Gateway contain a SQL injection flaw that lets an unauthenticated re…EPSS 81%analysed8.8CVE-2020-11852Microfocus secure messaging gateway os command injection vulnerabilityDKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020…EPSS 1.4%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed8.7CVE-2025-4008Meteobridge web interface command injection without authenticationThe Meteobridge web interface, built from CGI shell scripts and C, exposes an endpoint vulnerable to command injection. Because the endpoint also lac…KEVEPSS 94%analysed6.1CVE-2025-59689Libraesva ESG command injection via compressed email attachmentLibraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachme…KEVEPSS 1.9%analysed

Source: NIST National Vulnerability Database (record CVE-2018-12465), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.